CVE-2006-3649

EXPLOITED

Microsoft Visual Basic for Applications SDK 6.0-6.4 - Buffer Overflow via Document Properties

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2006-3649 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.

References (8)

Core 8
Core References
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/159484
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21408
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3214
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19414
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A694
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016656

Scores

EPSS 0.1017
EPSS Percentile 95.2%

Details

VulnCheck KEV 2006-08-08
Status published
Products (3)
microsoft/visual_basic 6.2 (2 CPE variants)
microsoft/visual_basic 6.3
microsoft/visual_basic 6.4
Published Aug 09, 2006
Tracked Since Feb 18, 2026